# Update a customer's payment details

Update a customer's saved payment details by submitting a single-use token from Hosted Fields to the Secure Tokens update-account endpoint.

An AI skill is available for this guide, get it on the [Skills Marketplace (GitHub)](https://github.com/payroc/skills).

If a customer uses Hosted Fields to change their payment details, our gateway returns a single-use token that represents the updated payment details. To update the customer’s saved payment details, send the single-use token to our gateway to update the secure token.

You can use a single-use token to update only the payment details linked to a secure token. To update the customer’s contact details or the merchant-initiated transaction (MIT) agreement, go to Update a secure token.

<a id="before-you-begin"></a>
## Before you begin

Make sure that you’ve set up your integration to [save payment details](/guides/payments/hosted-fields/save-payment-details-overview).

[Authenticate your requests](/api/authentication) before making API calls. If your request fails, see [Errors](/api/errors).

<a id="headers"></a>
### Headers

To create the header of each POST request, you must include the following parameters:

- **Content-Type:** Include application/json as the value for this parameter.
- **Authorization:** Include your Bearer token in this parameter.
- **Idempotency-Key:** Include a UUID v4 to make the request idempotent.

```curl
-H "Content-Type: application/json"
-H "Authorization: <Bearer token>"
-H "Idempotency-Key: <UUID v4>"
```

To create the header of each GET request, include the Authorization header parameter.

```curl
-H "Authorization: <Bearer token>"
```

<a id="errors"></a>
### Errors

Make sure that your integration can handle errors. If a request is unsuccessful, we return an error that follows the [RFC 7807 format](https://www.rfc-editor.org/rfc/rfc7807). For more information about errors, go to [Errors](/api/errors).

<a id="integration-steps"></a>
## Integration steps

1. List secure tokens.
2. Generate a session token.
3. Update the JavaScript library.
4. Update the secure token.

<a id="step-1-list-secure-tokens"></a>
## Step 1. List secure tokens

Before you update the customer’s payment details, you need the secureTokenId of the secure token that represents the customer's payments details.

To search for the secureTokenId, use our List Secure Tokens method to view all the secure tokens associated with the processing terminal. You can use query parameters to filter your search, for example, you can filter by the customer’s name or email address.

To view the secure tokens associated with the processing terminal, send a GET request to our Secure Tokens endpoint.

| Environment | URL |
| --- | --- |
| Test | [https://api.uat.payroc.com/v1/processing-terminals/\{processingTerminalId\}/secure-tokens](https://api.uat.payroc.com/v1/processing-terminals/%7BprocessingTerminalId%7D/secure-tokens) |
| Production | [https://api.payroc.com/v1/processing-terminals/\{processingTerminalId\}/secure-tokens](https://api.payroc.com/v1/processing-terminals/%7BprocessingTerminalId%7D/secure-tokens) |

<a id="request-parameters"></a>
### Request parameters

To create your request, use the following parameters:

<a id="schema-request"></a>
### Schema (`request`)

[Request schema for `GET /processing-terminals/{processingTerminalId}/secure-tokens`](/api/list-secure-tokens)

<a id="example-request"></a>
### Example request

<a id="request"></a>
### Request

GET [https://api.payroc.com/v1/processing-terminals/\{processingTerminalId\}/secure-tokens](https://api.payroc.com/v1/processing-terminals/%7BprocessingTerminalId%7D/secure-tokens)

**`Paginated Secure Token`**

```curl
curl -G https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens \
     -H "Authorization: Bearer <token>" \
     -d after=8516 \
     -d before=2571 \
     --data-urlencode customerName=Sarah%20Hazel%20Hopper \
     --data-urlencode email=sarah.hopper@example.com \
     -d first6=453985 \
     -d last4=7062 \
     -d limit=25 \
     -d phone=2025550165 \
     -d secureTokenId=MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa \
     -d token=296753123456
```

**`Paginated Secure Token`**

```python
import requests

url = "https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens"

querystring = {"after":"8516","before":"2571","customerName":"Sarah%20Hazel%20Hopper","email":"sarah.hopper@example.com","first6":"453985","last4":"7062","limit":"25","phone":"2025550165","secureTokenId":"MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa","token":"296753123456"}

headers = {"Authorization": "Bearer <token>"}

response = requests.get(url, headers=headers, params=querystring)

print(response.json())
```

**`Paginated Secure Token`**

```javascript
const url = 'https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens?after=8516&before=2571&customerName=Sarah%2520Hazel%2520Hopper&email=sarah.hopper%40example.com&first6=453985&last4=7062&limit=25&phone=2025550165&secureTokenId=MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa&token=296753123456';
const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

**`Paginated Secure Token`**

```go
package main

import (
	"fmt"
	"net/http"
	"io"
)

func main() {

	url := "https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens?after=8516&before=2571&customerName=Sarah%2520Hazel%2520Hopper&email=sarah.hopper%40example.com&first6=453985&last4=7062&limit=25&phone=2025550165&secureTokenId=MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa&token=296753123456"

	req, _ := http.NewRequest("GET", url, nil)

	req.Header.Add("Authorization", "Bearer <token>")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

**`Paginated Secure Token`**

```ruby
require 'uri'
require 'net/http'

url = URI("https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens?after=8516&before=2571&customerName=Sarah%2520Hazel%2520Hopper&email=sarah.hopper%40example.com&first6=453985&last4=7062&limit=25&phone=2025550165&secureTokenId=MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa&token=296753123456")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'

response = http.request(request)
puts response.read_body
```

**`Paginated Secure Token`**

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.get("https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens?after=8516&before=2571&customerName=Sarah%2520Hazel%2520Hopper&email=sarah.hopper%40example.com&first6=453985&last4=7062&limit=25&phone=2025550165&secureTokenId=MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa&token=296753123456")
  .header("Authorization", "Bearer <token>")
  .asString();
```

**`Paginated Secure Token`**

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens?after=8516&before=2571&customerName=Sarah%2520Hazel%2520Hopper&email=sarah.hopper%40example.com&first6=453985&last4=7062&limit=25&phone=2025550165&secureTokenId=MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa&token=296753123456', [
  'headers' => [
    'Authorization' => 'Bearer <token>',
  ],
]);

echo $response->getBody();
```

**`Paginated Secure Token`**

```csharp
using RestSharp;

var client = new RestClient("https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens?after=8516&before=2571&customerName=Sarah%2520Hazel%2520Hopper&email=sarah.hopper%40example.com&first6=453985&last4=7062&limit=25&phone=2025550165&secureTokenId=MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa&token=296753123456");
var request = new RestRequest(Method.GET);
request.AddHeader("Authorization", "Bearer <token>");
IRestResponse response = client.Execute(request);
```

**`Paginated Secure Token`**

```swift
import Foundation

let headers = ["Authorization": "Bearer <token>"]

let request = NSMutableURLRequest(url: NSURL(string: "https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens?after=8516&before=2571&customerName=Sarah%2520Hazel%2520Hopper&email=sarah.hopper%40example.com&first6=453985&last4=7062&limit=25&phone=2025550165&secureTokenId=MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa&token=296753123456")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "GET"
request.allHTTPHeaderFields = headers

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```

<a id="response-fields"></a>
### Response fields

If your request is successful, we return a list of secure tokens associated with the processing terminal. The response contains the following fields:

<a id="schema-responsebody"></a>
### Schema (`response.body`)

[Response body schema for `GET /processing-terminals/{processingTerminalId}/secure-tokens`](/api/list-secure-tokens)

<a id="example-response"></a>
### Example response

<a id="response-200"></a>
### Response (200)

```json
{
  "limit": 2,
  "count": 2,
  "hasMore": true,
  "data": [
    {
      "secureTokenId": "MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa",
      "processingTerminalId": "1234001",
      "source": {
        "type": "card",
        "cardNumber": "453985******7062",
        "cardholderName": "Sarah Hopper",
        "expiryDate": "1230"
      },
      "token": "296753123456",
      "status": "notValidated",
      "mitAgreement": "unscheduled",
      "customer": {
        "firstName": "Sarah",
        "lastName": "Hopper",
        "dateOfBirth": "1990-07-15",
        "referenceNumber": "Customer-12",
        "billingAddress": {
          "address1": "1 Example Ave.",
          "address2": "Example Address Line 2",
          "address3": "Example Address Line 3",
          "city": "Chicago",
          "state": "Illinois",
          "country": "US",
          "postalCode": "60056"
        },
        "shippingAddress": {
          "recipientName": "Sarah Hopper",
          "address": {
            "address1": "1 Example Ave.",
            "address2": "Example Address Line 2",
            "address3": "Example Address Line 3",
            "city": "Chicago",
            "state": "Illinois",
            "country": "US",
            "postalCode": "60056"
          }
        }
      }
    },
    {
      "secureTokenId": "MREF_fe0d9876-cba5-432f-e10d-9cb87654a3f2e1",
      "processingTerminalId": "1234001",
      "source": {
        "type": "card",
        "cardNumber": "500165******0000",
        "cardholderName": "Sarah Hazel Hopper",
        "expiryDate": "0328"
      },
      "token": "307864234567",
      "status": "notValidated",
      "mitAgreement": "unscheduled",
      "customer": {
        "firstName": "Sarah",
        "lastName": "Hopper",
        "dateOfBirth": "1990-07-15",
        "referenceNumber": "Customer-12",
        "billingAddress": {
          "address1": "1 Example Ave.",
          "address2": "Example Address Line 2",
          "address3": "Example Address Line 3",
          "city": "Chicago",
          "state": "Illinois",
          "country": "US",
          "postalCode": "60056"
        },
        "shippingAddress": {
          "recipientName": "Sarah Hopper",
          "address": {
            "address1": "1 Example Ave.",
            "address2": "Example Address Line 2",
            "address3": "Example Address Line 3",
            "city": "Chicago",
            "state": "Illinois",
            "country": "US",
            "postalCode": "60056"
          }
        }
      },
      "customFields": [
        {
          "name": "yourCustomField",
          "value": "abc123"
        }
      ]
    }
  ],
  "links": [
    {
      "rel": "next",
      "method": "get",
      "href": "https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens?limit=2&after=MREF_fe0d9876-cba5-432f-e10d-9cb87654a3f2e1"
    },
    {
      "rel": "previous",
      "method": "get",
      "href": "https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens?limit=2&before=MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa"
    }
  ]
}
```

<a id="step-2-generate-a-session-token"></a>
## Step 2. Generate a session token

When you generate the session token, you need to include the secureTokenId of the secure token that you want to update.

To generate a session token, send a POST request to our Processing Terminals endpoint.

| Environment | URL |
| --- | --- |
| Test | [https://api.uat.payroc.com/v1/processing-terminals/\{processingTerminalId\}/hosted-fields-sessions](https://api.uat.payroc.com/v1/processing-terminals/%7BprocessingTerminalId%7D/hosted-fields-sessions) |
| Production | [https://api.payroc.com/v1/processing-terminals/\{processingTerminalId\}/hosted-fields-sessions](https://api.payroc.com/v1/processing-terminals/%7BprocessingTerminalId%7D/hosted-fields-sessions) |

<a id="request-parameters-1"></a>
### Request parameters

To create the body of your request, use the following parameters:

<a id="schema-requestbody"></a>
### Schema (`request.body`)

[Request body schema for `POST /processing-terminals/{processingTerminalId}/hosted-fields-sessions`](/api/create-session)

<a id="example-request-1"></a>
### Example request

<a id="request-1"></a>
### Request

POST [https://api.payroc.com/v1/processing-terminals/\{processingTerminalId\}/hosted-fields-sessions](https://api.payroc.com/v1/processing-terminals/%7BprocessingTerminalId%7D/hosted-fields-sessions)

**`Create session`**

```curl
curl -X POST https://api.payroc.com/v1/processing-terminals/1234001/hosted-fields-sessions \
     -H "Idempotency-Key: 8e03978e-40d5-43e8-bc93-6894a57f9324" \
     -H "Authorization: Bearer <token>" \
     -H "Content-Type: application/json" \
     -d '{
  "libVersion": "1.1.0.123456",
  "scenario": "payment"
}'
```

**`Create session`**

```python
import requests

url = "https://api.payroc.com/v1/processing-terminals/1234001/hosted-fields-sessions"

payload = {
    "libVersion": "1.1.0.123456",
    "scenario": "payment"
}
headers = {
    "Idempotency-Key": "8e03978e-40d5-43e8-bc93-6894a57f9324",
    "Authorization": "Bearer <token>",
    "Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers)

print(response.json())
```

**`Create session`**

```javascript
const url = 'https://api.payroc.com/v1/processing-terminals/1234001/hosted-fields-sessions';
const options = {
  method: 'POST',
  headers: {
    'Idempotency-Key': '8e03978e-40d5-43e8-bc93-6894a57f9324',
    Authorization: 'Bearer <token>',
    'Content-Type': 'application/json'
  },
  body: '{"libVersion":"1.1.0.123456","scenario":"payment"}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

**`Create session`**

```go
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://api.payroc.com/v1/processing-terminals/1234001/hosted-fields-sessions"

	payload := strings.NewReader("{\n  \"libVersion\": \"1.1.0.123456\",\n  \"scenario\": \"payment\"\n}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("Idempotency-Key", "8e03978e-40d5-43e8-bc93-6894a57f9324")
	req.Header.Add("Authorization", "Bearer <token>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

**`Create session`**

```ruby
require 'uri'
require 'net/http'

url = URI("https://api.payroc.com/v1/processing-terminals/1234001/hosted-fields-sessions")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Idempotency-Key"] = '8e03978e-40d5-43e8-bc93-6894a57f9324'
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n  \"libVersion\": \"1.1.0.123456\",\n  \"scenario\": \"payment\"\n}"

response = http.request(request)
puts response.read_body
```

**`Create session`**

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://api.payroc.com/v1/processing-terminals/1234001/hosted-fields-sessions")
  .header("Idempotency-Key", "8e03978e-40d5-43e8-bc93-6894a57f9324")
  .header("Authorization", "Bearer <token>")
  .header("Content-Type", "application/json")
  .body("{\n  \"libVersion\": \"1.1.0.123456\",\n  \"scenario\": \"payment\"\n}")
  .asString();
```

**`Create session`**

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.payroc.com/v1/processing-terminals/1234001/hosted-fields-sessions', [
  'body' => '{
  "libVersion": "1.1.0.123456",
  "scenario": "payment"
}',
  'headers' => [
    'Authorization' => 'Bearer <token>',
    'Content-Type' => 'application/json',
    'Idempotency-Key' => '8e03978e-40d5-43e8-bc93-6894a57f9324',
  ],
]);

echo $response->getBody();
```

**`Create session`**

```csharp
using RestSharp;

var client = new RestClient("https://api.payroc.com/v1/processing-terminals/1234001/hosted-fields-sessions");
var request = new RestRequest(Method.POST);
request.AddHeader("Idempotency-Key", "8e03978e-40d5-43e8-bc93-6894a57f9324");
request.AddHeader("Authorization", "Bearer <token>");
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"libVersion\": \"1.1.0.123456\",\n  \"scenario\": \"payment\"\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

**`Create session`**

```swift
import Foundation

let headers = [
  "Idempotency-Key": "8e03978e-40d5-43e8-bc93-6894a57f9324",
  "Authorization": "Bearer <token>",
  "Content-Type": "application/json"
]
let parameters = [
  "libVersion": "1.1.0.123456",
  "scenario": "payment"
] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://api.payroc.com/v1/processing-terminals/1234001/hosted-fields-sessions")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```

<a id="response-fields-1"></a>
### Response fields

If your request is successful, our gateway generates a session token. The response contains the following fields:

<a id="schema-responsebody-1"></a>
### Schema (`response.body`)

[Response body schema for `POST /processing-terminals/{processingTerminalId}/hosted-fields-sessions`](/api/create-session)

<a id="example-response-1"></a>
### Example response

<a id="response-201"></a>
### Response (201)

```json
{
  "processingTerminalId": "1234001",
  "token": "abcdef1234567890abcdef1234567890",
  "expiresAt": "2025-07-02T15:30:00.123456789+02:00"
}
```

<a id="step-3-update-the-javascript-library"></a>
## Step 3. Update the JavaScript library

In the JavaScript configuration, change the value for the mode parameter from payment to `tokenization`.

**`Card`**

```js
<script
  src="https://cdn.uat.payroc.com/js/hosted-fields/hosted-fields-1.7.0.261457.js"
  integrity="sha384-m1A0nfFYa8sAfpDN0d60o4ztd/aCPC2xDVaOT31Urrmn4xypfHqgHQMayZeIK1PM"
  crossorigin="anonymous"
></script>

<script>
  const cardForm = new Payroc.hostedFields({
    sessionToken: YOUR_SESSION_TOKEN,
    mode: "tokenization",
    fields: {
      card: {
        cardholderName: {
          target: ".card-holder-name",
          errorTarget: ".card-holder-name-error",
          placeholder: "Cardholder Name",
        },
        cardNumber: {
          target: ".card-number",
          errorTarget: ".card-number-error",
          placeholder: "1234 5678 1234 1211",
        },
        cvv: {
          wrapperTarget: ".card-cvv-wrapper",
          target: ".card-cvv",
          errorTarget: ".card-cvv-error",
          placeholder: "CVV",
        },
        expiryDate: {
          target: ".card-expiry",
          errorTarget: ".card-expiry-error",
          placeholder: "MM/YY",
        },
        submit: {
          target: ".submit-button",
          value: "Submit",
        },
      },
    },
  });
</script>
```

**`ACH`**

```js
<script
  src="https://cdn.uat.payroc.com/js/hosted-fields/hosted-fields-1.7.0.261457.js"
  integrity="sha384-m1A0nfFYa8sAfpDN0d60o4ztd/aCPC2xDVaOT31Urrmn4xypfHqgHQMayZeIK1PM"
  crossorigin="anonymous"
></script>

<script>
  const achForm = new Payroc.hostedFields({
    sessionToken: YOUR_SESSION_TOKEN,
    mode: "tokenization",
    fields: {
      ach: {
        nameOnAccount: {
          target: ".ach-account-holder",
          errorTarget: ".ach-account-holder-error",
          placeholder: "Accountholder Name",
        },
        accountType: {
          target: ".ach-account-type",
          errorTarget: ".ach-account-type-error",
        },
        achAccountNumber: {
          target: ".ach-account-number",
          errorTarget: ".ach-account-number-error",
          placeholder: "Account Number",
        },
        routingNumber: {
          target: ".ach-routing-number",
          errorTarget: ".ach-routing-number-error",
          placeholder: "Routing Number",
        },
        submit: {
          target: ".submit-button",
          value: "Submit",
        },
      },
    },
  });
</script>
```

**`PAD`**

```js
<script
  src="https://cdn.uat.payroc.com/js/hosted-fields/hosted-fields-1.7.0.261457.js"
  integrity="sha384-m1A0nfFYa8sAfpDN0d60o4ztd/aCPC2xDVaOT31Urrmn4xypfHqgHQMayZeIK1PM"
  crossorigin="anonymous"
></script>

<script>
  const padForm = new Payroc.hostedFields({
    sessionToken: YOUR_SESSION_TOKEN,
    mode: "tokenization",
    fields: {
      pad: {
        nameOnAccount: {
          target: ".pad-account-holder",
          errorTarget: ".pad-account-holder-error",
          placeholder: "Accountholder Name",
        },
        padAccountNumber: {
          target: ".pad-account-number",
          errorTarget: ".pad-account-number-error",
          placeholder: "Account Number",
        },
        institutionNumber: {
          target: ".pad-institution-number",
          errorTarget: ".pad-institution-number-error",
          placeholder: "Institution Number",
        },
        transitNumber: {
          target: ".pad-transit-number",
          errorTarget: ".pad-transit-number-error",
          placeholder: "Transit Number",
        },
        submit: {
          target: ".submit-button",
          value: "Submit",
        },
      },
    },
  });
</script>
```

<a id="step-4-update-the-secure-token"></a>
## Step 4. Update the secure token

After the customer submits their new payment details and you receive the single-use token from the submissionSuccess event, send the single-use token to our gateway to update the secure token.

To send the single-use token to our gateway, send a POST request to our Secure Tokens endpoint.

| Environment | URL |
| --- | --- |
| Test | [https://api.uat.payroc.com/v1/processing-terminals/\{processingTerminalId\}/secure-tokens/\{secureTokenId\}/update-account](https://api.uat.payroc.com/v1/processing-terminals/%7BprocessingTerminalId%7D/secure-tokens/%7BsecureTokenId%7D/update-account) |
| Production | [https://api.payroc.com/v1/processing-terminals/\{processingTerminalId\}/secure-tokens/\{secureTokenId\}/update-account](https://api.payroc.com/v1/processing-terminals/%7BprocessingTerminalId%7D/secure-tokens/%7BsecureTokenId%7D/update-account) |

<a id="request-parameters-2"></a>
### Request parameters

To create the body of your request, use the following parameters:

<a id="schema-requestbody-1"></a>
### Schema (`request.body`)

[Request body schema for `POST /processing-terminals/{processingTerminalId}/secure-tokens/{secureTokenId}/update-account`](/api/account-update)

<a id="example-request-2"></a>
### Example request

<a id="request-2"></a>
### Request

POST [https://api.payroc.com/v1/processing-terminals/\{processingTerminalId\}/secure-tokens/\{secureTokenId\}/update-account](https://api.payroc.com/v1/processing-terminals/%7BprocessingTerminalId%7D/secure-tokens/%7BsecureTokenId%7D/update-account)

**`Update account details`**

```curl
curl -X POST https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens/MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa/update-account \
     -H "Idempotency-Key: 8e03978e-40d5-43e8-bc93-6894a57f9324" \
     -H "Authorization: Bearer <token>" \
     -H "Content-Type: application/json" \
     -d '{
  "type": "singleUseToken",
  "token": "abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890"
}'
```

**`Update account details`**

```python
import requests

url = "https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens/MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa/update-account"

payload = {
    "type": "singleUseToken",
    "token": "abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890"
}
headers = {
    "Idempotency-Key": "8e03978e-40d5-43e8-bc93-6894a57f9324",
    "Authorization": "Bearer <token>",
    "Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers)

print(response.json())
```

**`Update account details`**

```javascript
const url = 'https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens/MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa/update-account';
const options = {
  method: 'POST',
  headers: {
    'Idempotency-Key': '8e03978e-40d5-43e8-bc93-6894a57f9324',
    Authorization: 'Bearer <token>',
    'Content-Type': 'application/json'
  },
  body: '{"type":"singleUseToken","token":"abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890"}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

**`Update account details`**

```go
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens/MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa/update-account"

	payload := strings.NewReader("{\n  \"type\": \"singleUseToken\",\n  \"token\": \"abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890\"\n}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("Idempotency-Key", "8e03978e-40d5-43e8-bc93-6894a57f9324")
	req.Header.Add("Authorization", "Bearer <token>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

**`Update account details`**

```ruby
require 'uri'
require 'net/http'

url = URI("https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens/MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa/update-account")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Idempotency-Key"] = '8e03978e-40d5-43e8-bc93-6894a57f9324'
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n  \"type\": \"singleUseToken\",\n  \"token\": \"abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890\"\n}"

response = http.request(request)
puts response.read_body
```

**`Update account details`**

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens/MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa/update-account")
  .header("Idempotency-Key", "8e03978e-40d5-43e8-bc93-6894a57f9324")
  .header("Authorization", "Bearer <token>")
  .header("Content-Type", "application/json")
  .body("{\n  \"type\": \"singleUseToken\",\n  \"token\": \"abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890\"\n}")
  .asString();
```

**`Update account details`**

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens/MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa/update-account', [
  'body' => '{
  "type": "singleUseToken",
  "token": "abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890"
}',
  'headers' => [
    'Authorization' => 'Bearer <token>',
    'Content-Type' => 'application/json',
    'Idempotency-Key' => '8e03978e-40d5-43e8-bc93-6894a57f9324',
  ],
]);

echo $response->getBody();
```

**`Update account details`**

```csharp
using RestSharp;

var client = new RestClient("https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens/MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa/update-account");
var request = new RestRequest(Method.POST);
request.AddHeader("Idempotency-Key", "8e03978e-40d5-43e8-bc93-6894a57f9324");
request.AddHeader("Authorization", "Bearer <token>");
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"type\": \"singleUseToken\",\n  \"token\": \"abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890\"\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

**`Update account details`**

```swift
import Foundation

let headers = [
  "Idempotency-Key": "8e03978e-40d5-43e8-bc93-6894a57f9324",
  "Authorization": "Bearer <token>",
  "Content-Type": "application/json"
]
let parameters = [
  "type": "singleUseToken",
  "token": "abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890"
] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens/MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa/update-account")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```

<a id="response-fields-2"></a>
### Response fields

If your request is successful, we update the payment details associated with the secure token. The response contains the following fields:

**Note:** When we update the payment details associated with the secure token, we change only the payment details that the secure token represents. The values for the secureTokenId parameter and the token parameter stay the same.

<a id="schema-responsebody-2"></a>
### Schema (`response.body`)

[Response body schema for `POST /processing-terminals/{processingTerminalId}/secure-tokens/{secureTokenId}/update-account`](/api/account-update)

<a id="example-response-2"></a>
### Example response

<a id="response-200-1"></a>
### Response (200)

```json
{
  "secureTokenId": "MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa",
  "processingTerminalId": "1234001",
  "source": {
    "type": "card",
    "cardNumber": "453985******7062",
    "cardholderName": "Sarah Hazel Hopper",
    "expiryDate": "1230"
  },
  "token": "296753123456",
  "status": "notValidated",
  "mitAgreement": "unscheduled",
  "customer": {
    "firstName": "Sarah",
    "lastName": "Hopper",
    "dateOfBirth": "1990-07-15",
    "referenceNumber": "Customer-12",
    "billingAddress": {
      "address1": "1 Example Ave.",
      "address2": "Example Address Line 2",
      "address3": "Example Address Line 3",
      "city": "Chicago",
      "state": "Illinois",
      "country": "US",
      "postalCode": "60056"
    },
    "shippingAddress": {
      "recipientName": "Sarah Hopper",
      "address": {
        "address1": "1 Example Ave.",
        "address2": "Example Address Line 2",
        "address3": "Example Address Line 3",
        "city": "Chicago",
        "state": "Illinois",
        "country": "US",
        "postalCode": "60056"
      }
    },
    "contactMethods": [
      {
        "type": "email",
        "value": "sarah.hopper@example.com"
      }
    ],
    "notificationLanguage": "en"
  },
  "customFields": [
    {
      "name": "yourCustomField",
      "value": "abc123"
    }
  ]
}
```
